Who we are
Runzemi is operated by [[Company legal name, Inc.]], [[a Delaware corporation]] (“Runzemi”, “we”, “us” or “our”), located at [[Street address, City, State ZIP, United States]].
This Privacy Policy applies to personal information we process when you:
- visit this website;
- sign in to and use the Runzemi dashboard at yuzu-actions.vercel.app;
- install and use the Runzemi GitHub App;
- run GitHub Actions jobs on Runzemi runners; or
- contact us.
“Personal information” means information that identifies you or can reasonably be linked to you. [[Company legal name, Inc.]] is the controller of the personal information described in this policy, except as explained below. Your use of Runzemi is also governed by our Terms of Service and Acceptable Use Policy.
Content you run through Runzemi. Your repositories, workflow files and job output can contain personal information about other people – for example, a commit author’s name and email address, or test data printed to a log. We process that content only to run your jobs and provide Runzemi to the workspace it belongs to, and that workspace’s owners decide what goes into it. If you have a question about personal information that one of our customers processes using Runzemi, please contact that customer.
Information we collect
We collect information from you, from GitHub when you connect it, and automatically when you use our website and dashboard. We also create records when your jobs run.
Information you provide
- Account details. You sign in to the dashboard with GitHub through our authentication provider, WorkOS. When you do, we receive your name, email address, GitHub username and user ID, and avatar URL. We don’t receive your GitHub password.
- Workspace membership. The workspaces and organizations you belong to, and your role in each: owner, admin, billing or developer. WorkOS keeps a record of these memberships, and if someone invites you to a workspace, WorkOS uses your email address to send you the invitation.
- Settings and approvals. Choices you make in the dashboard, such as a daily spend cap and a concurrency limit, and the workflow changes you review and approve.
- Billing information. You enter payment details directly with Stripe, our payment processor, and we don’t store full card numbers. We keep your Stripe customer and subscription IDs, invoices, and records of included compute and added funds.
- Messages to us. When you email us – for example at support@[[your-domain.com]] – we keep your email address, your message and our replies.
Information from GitHub
When you install the Runzemi GitHub App on a personal account or organization, you choose which repositories it can access. Runzemi sees only the repositories you grant the App. Through the App, GitHub sends us:
- installation IDs and the name of the account or organization the App is installed on;
- the IDs and names of the repositories you grant; and
- event notifications (webhooks) for the repositories you grant, including for workflow jobs that don’t run on Runzemi. These include the branch, commit SHA and message, workflow and job names, job status, runner labels and timings (when a job was queued, started and completed); the GitHub username, user ID and avatar of the person who triggered the event; and, for workflow runs, the name and email address of the commit’s author and committer.
If you use workflow migration, we read the workflow files in .github/workflows of the repository and branch you select, show you the exact runs-on changes, and commit only the changes you approve – to that branch, or to a separate branch for a pull request, for example when the branch is protected. The commit message names the GitHub username of the person who requested the migration, as in Requested-by: @username via Runzemi, and is visible to anyone who can see the repository. We keep an audit record of each migration attempt.
Information created when your jobs run
- Your job’s code and secrets. Each job runs on a fresh, single-use virtual machine (VM) operated by our cloud infrastructure provider. Your workflow code and any secrets you pass to the job are processed on that VM only to run the job. The VM and its disk are deleted after the job, and we don’t keep a job’s working files.
- Job logs. The runner masks secrets in job output on the VM, before the output leaves it. The masked logs are stored in private object storage (Cloudflare R2) for 30 days. We also keep limited log metadata: sizes, hashes, sequence numbers and deletion records. Masking can’t catch every form of a secret – for example, a value your job encodes before printing it – so avoid writing sensitive data to job output.
- Usage records. A usage ledger of the vCPU-seconds each job used, which we use to bill you and to show usage and run history in the dashboard.
Information collected automatically
- Server logs. When you visit this website or the dashboard, our hosting providers process standard server logs – your IP address, user agent and the URL you requested – to deliver pages and keep Runzemi secure.
- Cookies. The dashboard sets cookies to keep you signed in and to remember your preferences, such as whether you collapsed the sidebar. See Cookies.
- No tracking on this website. This website uses no analytics, sets no cookies and has no advertising or tracking pixels.
How we use information
We use personal information to:
- Provide and operate Runzemi – sign you in, show your workspaces and repositories, start and run your jobs, stream and store logs, show run history and charts, apply the workflow changes you approve, and keep it running reliably.
- Bill you – manage your subscription and added funds through Stripe, meter usage per second, apply included compute and volume discounts, enforce your daily spend cap and concurrency limit, and keep invoices and accounting records.
- Keep Runzemi secure and prevent abuse – authenticate requests, detect and investigate fraud, abuse and security incidents, and enforce our Terms of Service and Acceptable Use Policy.
- Support you – answer your questions and look into problems you report.
- Communicate with you about Runzemi – for example, about your account, billing, security issues or changes to our terms and policies.
- Comply with the law – meet tax, accounting and other legal obligations, respond to lawful requests, and protect our rights and the rights of others.
What we don’t do
- We don’t sell your personal information, and we don’t share it for cross-context behavioral advertising.
- We don’t use your personal information to show you targeted advertising.
- We don’t make decisions about you based solely on automated processing that produce legal or similarly significant effects, except that we automatically pause jobs when your balance, your daily spend cap or a payment issue (such as a failed, disputed or refunded payment) requires it.
- We commit not to use your code, workflow files, secrets or job logs to train artificial intelligence or machine learning models.
Legal bases (EEA, UK and Switzerland)
If you’re in the European Economic Area (EEA), the United Kingdom or Switzerland, we rely on the following legal bases under the GDPR, the UK GDPR and the Swiss Federal Act on Data Protection:
- Performance of a contract – to create your account, run your jobs, store and show your logs, and bill you, as described in our Terms of Service.
- Legitimate interests – to keep our website and Runzemi secure, prevent fraud and abuse, enforce our terms, keep Runzemi reliable, reply to people who contact us, and carry out business transfers. We weigh these interests against your rights, and you can object (see Rights in the EEA, UK and Switzerland).
- Legal obligation – to keep billing and tax records and to respond to lawful requests from authorities.
- Consent – where we ask for it. You can withdraw consent at any time; this doesn’t affect processing that took place before you withdrew it.
How we share information
We share personal information only as described in this section.
Service providers
We use the companies below to run Runzemi. They process personal information on our behalf and only to provide their services to us, except where noted.
| Provider | Purpose | Information involved |
|---|---|---|
| WorkOS | Authentication, sessions, organization memberships and invitation emails: signing you in with GitHub and recording which workspaces you belong to. | Name, email address, GitHub username and user ID, avatar URL; workspace memberships; email addresses of people invited to a workspace |
| GitHub | The repository integration you authorize: the Runzemi GitHub App, job routing and the workflow commits you approve. GitHub acts as an independent controller. | Installation, repository and workflow event information, including commit details and GitHub usernames; job status and output |
| Stripe | Payments, subscriptions, invoices and the billing portal. Stripe acts as an independent controller for some purposes, such as fraud prevention and its own legal obligations. | Payment details, billing contact details, subscription and invoice records |
| Convex | Application database and backend for Runzemi. | Account, workspace, repository, job, usage and billing records, and the event records we receive from GitHub, WorkOS and Stripe |
| Vercel | Hosting for this website and the dashboard. | Server logs (IP address, user agent, requested URL) |
| Cloudflare | Private object storage (R2) for job logs. | Masked job logs |
| Cloud infrastructure provider | The single-use virtual machines that run your jobs. | Your job’s code, data and secrets, for the duration of the job |
| Email provider | Sending and receiving support and account email. | Name, email address, message content |
WorkOS
- Purpose
- Authentication, sessions, organization memberships and invitation emails: signing you in with GitHub and recording which workspaces you belong to.
- Information involved
- Name, email address, GitHub username and user ID, avatar URL; workspace memberships; email addresses of people invited to a workspace
GitHub
- Purpose
- The repository integration you authorize: the Runzemi GitHub App, job routing and the workflow commits you approve. GitHub acts as an independent controller.
- Information involved
- Installation, repository and workflow event information, including commit details and GitHub usernames; job status and output
Stripe
- Purpose
- Payments, subscriptions, invoices and the billing portal. Stripe acts as an independent controller for some purposes, such as fraud prevention and its own legal obligations.
- Information involved
- Payment details, billing contact details, subscription and invoice records
Convex
- Purpose
- Application database and backend for Runzemi.
- Information involved
- Account, workspace, repository, job, usage and billing records, and the event records we receive from GitHub, WorkOS and Stripe
Vercel
- Purpose
- Hosting for this website and the dashboard.
- Information involved
- Server logs (IP address, user agent, requested URL)
Cloudflare
- Purpose
- Private object storage (R2) for job logs.
- Information involved
- Masked job logs
Cloud infrastructure provider
- Purpose
- The single-use virtual machines that run your jobs.
- Information involved
- Your job’s code, data and secrets, for the duration of the job
Email provider
- Purpose
- Sending and receiving support and account email.
- Information involved
- Name, email address, message content
GitHub, at your direction
When you install the GitHub App, run jobs on Runzemi or approve a workflow migration, information moves between Runzemi and GitHub because you asked for it: the runner reports your job’s status and output back to GitHub Actions, and the runs-on changes you approve are committed to your repository, with the requester’s GitHub username in the commit message. GitHub handles that information under the GitHub General Privacy Statement. Stripe handles payment information under the Stripe Privacy Policy.
Within your workspace
Other members of a workspace can see the information in it according to their role – for example, its runs and job logs. Billing is managed by the workspace’s owners, admins and billing members; billing members don’t see repositories, runs or logs.
Legal requirements and safety
We may disclose information if we believe in good faith that the law, a subpoena or other legal process requires it, or that it’s necessary to protect the rights, property or safety of Runzemi, our users or others – including to enforce our terms and investigate abuse.
Business transfers
If we’re involved in a merger, acquisition, financing, reorganization, bankruptcy or sale of assets, personal information may be transferred as part of that transaction. We’ll take reasonable steps to keep it protected as described in this policy, and we’ll tell you if ownership or use of your information changes.
With your consent
We may share personal information for other purposes when you ask us to or agree to it.
Cookies
This website sets no cookies. It doesn’t use analytics, advertising or tracking cookies, pixels or similar technologies.
The dashboard sets a few first-party cookies, none of them for advertising or tracking:
| Cookie | What it does | Type | How long |
|---|---|---|---|
wos-session | Keeps you signed in. | Strictly necessary | Until you sign out or the session expires |
wos-auth-verifier | Secures the GitHub sign-in while it’s in progress. | Strictly necessary | Up to 10 minutes, during sign-in |
yuzu_sidebar | Remembers whether you collapsed the sidebar. Set only when you change it. | Functional | Up to 1 year |
PARAGLIDE_LOCALE | Remembers your language preference, if you choose one. | Functional | Up to 400 days |
wos-session- What it does
- Keeps you signed in.
- Type
- Strictly necessary
- How long
- Until you sign out or the session expires
wos-auth-verifier- What it does
- Secures the GitHub sign-in while it’s in progress.
- Type
- Strictly necessary
- How long
- Up to 10 minutes, during sign-in
yuzu_sidebar- What it does
- Remembers whether you collapsed the sidebar. Set only when you change it.
- Type
- Functional
- How long
- Up to 1 year
PARAGLIDE_LOCALE- What it does
- Remembers your language preference, if you choose one.
- Type
- Functional
- How long
- Up to 400 days
The strictly necessary cookies are needed for the dashboard to work, so we don’t ask for consent to use them; if you block them, you won’t be able to sign in. The functional cookies only remember choices you make in the dashboard. You can delete cookies at any time in your browser settings.
When you sign in, you pass through GitHub and WorkOS, and billing pages such as the billing portal are hosted by Stripe. Those services may set their own cookies under their own policies.
How long we keep information
We keep personal information only as long as we need it for the purposes in this policy.
| Information | How long we keep it |
|---|---|
| Job working files | Not retained. The VM and its disk are deleted after the job. |
| Job logs | 30 days, unless a workspace owner or admin deletes them sooner. Deleting revokes access immediately; the stored data is removed afterwards. |
| Account, workspace and job records | While your account is active, then deleted or de-identified within 90 days after it’s closed, except records we must keep for legal, tax, billing, dispute or security reasons. This includes run history, settings, log metadata, migration audit records and the event records we receive from GitHub, WorkOS and Stripe. |
| Billing and tax records | As long as the law requires, typically up to 7 years. |
| Support messages | As long as needed to resolve your request and keep a record of our conversation. |
| Server logs | A short period, under our hosting providers’ retention settings. |
| Backups | Overwritten on a regular schedule. |
Job working files
- How long we keep it
- Not retained. The VM and its disk are deleted after the job.
Job logs
- How long we keep it
- 30 days, unless a workspace owner or admin deletes them sooner. Deleting revokes access immediately; the stored data is removed afterwards.
Account, workspace and job records
- How long we keep it
- While your account is active, then deleted or de-identified within 90 days after it’s closed, except records we must keep for legal, tax, billing, dispute or security reasons. This includes run history, settings, log metadata, migration audit records and the event records we receive from GitHub, WorkOS and Stripe.
Billing and tax records
- How long we keep it
- As long as the law requires, typically up to 7 years.
Support messages
- How long we keep it
- As long as needed to resolve your request and keep a record of our conversation.
Server logs
- How long we keep it
- A short period, under our hosting providers’ retention settings.
Backups
- How long we keep it
- Overwritten on a regular schedule.
We may keep information longer when we need it to resolve disputes, enforce our agreements or comply with the law. When we no longer need information, we delete it or de-identify it.
Security
We use technical and organizational measures designed to protect personal information, including:
- encryption in transit (TLS) for traffic to and from our website, dashboard and services;
- access to production systems and data limited to the people who need it;
- credentials for GitHub, Stripe and our infrastructure kept on our servers and never sent to your browser;
- secrets masked in job output before it leaves the VM, and logs kept in private storage;
- a fresh VM for every job, deleted after the job and never reused.
No system is perfectly secure, and we can’t guarantee the security of your information. If you find a security issue, please report it to security@[[your-domain.com]].
International transfers
We’re based in the United States. We and our service providers process personal information in the United States and in other countries where those providers operate, which may have data protection laws different from those where you live.
When we transfer personal information from the EEA, the UK or Switzerland to a country that hasn’t been recognized as providing adequate protection, we rely on the Standard Contractual Clauses approved by the European Commission (with the UK International Data Transfer Addendum, or the amendments Swiss law requires, where they apply) or another valid transfer mechanism. Contact us for more information about these safeguards.
Your choices and rights
Wherever you live, you can:
- Control repository access. Change which repositories the Runzemi GitHub App can access, or uninstall it, in your GitHub settings at any time. Runzemi loses access to any repository you remove.
- Delete job logs. Workspace owners and admins can delete a job’s logs from the dashboard at any time. Access is revoked immediately and the stored data is removed afterwards. GitHub keeps its own copy of job output under its own settings.
- Update your profile. Your name, email address and avatar come from your GitHub account, so update them on GitHub.
- Manage billing. Owners, admins and billing members can update payment details and manage the subscription in the Stripe billing portal, opened from the dashboard.
- Close your account. Email support@[[your-domain.com]] to close your account. We delete or de-identify your personal information within 90 days after it’s closed, except what we must keep as described in How long we keep information.
- Ask us. Email privacy@[[your-domain.com]] to find out what we hold about you, correct it, get a copy or have it deleted.
Depending on where you live, you may have further rights, described in the next two sections. We won’t treat you differently for exercising any of them.
US state privacy rights
If you live in California or another US state with a comprehensive consumer privacy law – such as Colorado, Connecticut, Oregon, Texas or Virginia – you may have the rights below, subject to the exceptions in those laws. This section is also our notice at collection under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”).
Personal information we collect
In the past 12 months, we have collected the categories of personal information below. For each one, we list where it comes from, why we use it, the categories of recipients we disclose it to for business purposes and how long we keep it. Under “Kept for”, “account life” means while your account is active and up to 90 days after it’s closed, subject to the exceptions in How long we keep information.
Identifiers
- Examples
- Name, email address, GitHub username and user ID, IP address, account and Stripe customer IDs
- Sources
- You, GitHub (through WorkOS), automatic collection
- Purposes
- Providing Runzemi, billing, security, support
- Disclosed to
- WorkOS, Convex, Vercel, Stripe, email provider
- Kept for
- Account life; billing records: up to 7 years; server logs: a short period
Customer records
- Examples
- Name, email address, billing records
- Sources
- You, Stripe
- Purposes
- Billing, support, legal compliance
- Disclosed to
- Stripe, Convex, email provider
- Kept for
- Account life; billing records: up to 7 years
Commercial information
- Examples
- Plan and subscription, invoices, included compute and added funds, usage ledger, spend settings
- Sources
- You, Stripe, our systems
- Purposes
- Billing, spend controls, legal compliance
- Disclosed to
- Stripe, Convex
- Kept for
- Account life; billing and tax records: up to 7 years
Internet or network activity
- Examples
- Server logs, session data, workflow event records, job metadata and timings, audit records
- Sources
- Automatic collection, GitHub
- Purposes
- Providing Runzemi, security and abuse prevention
- Disclosed to
- Vercel, Convex, GitHub
- Kept for
- Server logs: a short period; other records: account life
Professional information
- Examples
- Organizations and workspaces you belong to and your role in each
- Sources
- You, GitHub, WorkOS
- Purposes
- Providing Runzemi, access control
- Disclosed to
- WorkOS, Convex
- Kept for
- Account life
Repository and job data
- Examples
- Repository and branch names, commit SHAs and messages, commit author and committer names and email addresses, GitHub usernames of people who trigger workflows, workflow files, job logs (which may contain personal information)
- Sources
- GitHub, your jobs
- Purposes
- Running your jobs, showing logs and run history
- Disclosed to
- Convex, Cloudflare, cloud infrastructure provider, GitHub
- Kept for
- Job logs: 30 days; other records: account life
Sensitive personal information
- Examples
- Secrets you pass to a job, which may include account credentials
- Sources
- Your jobs
- Purposes
- Running that job only
- Disclosed to
- Cloud infrastructure provider (on the job’s VM only)
- Kept for
- Not kept after the job
We use these categories for the purposes in How we use information. We don’t draw inferences from personal information to build a profile about you.
No sale or sharing
We don’t sell personal information or share it for cross-context behavioral advertising, and we haven’t done either in the past 12 months. We have no actual knowledge of selling or sharing the personal information of anyone under 16. If your browser sends an opt-out preference signal such as Global Privacy Control, we treat it as a valid request to opt out.
Sensitive personal information
Secrets you pass to a job may include account credentials, which the CCPA treats as sensitive personal information. We use them only to run that job – a use the CCPA permits without a right to limit – and we never use sensitive personal information to infer characteristics about you.
Your rights
- Know and access – the categories and specific pieces of personal information we hold about you, where it came from, why we use it and who we disclose it to.
- Delete – personal information we collected from you, subject to exceptions such as records we must keep for tax purposes.
- Correct – personal information that’s inaccurate.
- Portability – a copy of your personal information in a portable, readily usable format.
- Opt out of sale, sharing and targeted advertising – we don’t do any of these.
- Limit the use of sensitive personal information – we use it only as described above, so there’s nothing further to limit.
- Non-discrimination – we won’t deny you service, charge you a different price or give you a different quality of service because you exercised your rights.
How to make a request
Email privacy@[[your-domain.com]], ideally from the email address on your Runzemi account, and tell us which right you want to exercise.
Verification. To protect your information, we verify each request by confirming that you control the email address on your account – for example, by asking you to sign in or reply from that address. We may ask for more information if we need it, and we’ll use it only to verify your request.
Authorized agents. You can ask an authorized agent to make a request for you. We’ll ask for proof that you gave the agent signed permission, and we may ask you to confirm your identity with us directly, unless the agent holds a valid power of attorney.
Timing. We’ll confirm we received your request within 10 business days and respond within 45 days. If we need more time, we’ll tell you why and how much longer, within the limits the law allows.
Appeals. If we decline your request, we’ll explain why. You can appeal by replying to our decision or emailing privacy@[[your-domain.com]] with “Appeal” in the subject line. We’ll respond within the period your state’s law requires. If you disagree with the outcome, you can contact your state attorney general.
Rights in the EEA, UK and Switzerland
If you’re in the EEA, the UK or Switzerland, you have the right to:
- Access your personal information and receive a copy of it;
- Rectification – have inaccurate or incomplete information corrected;
- Erasure – have your information deleted in certain circumstances;
- Restriction – ask us to limit how we use it in certain circumstances;
- Objection – object to processing based on our legitimate interests;
- Portability – receive information you gave us in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible;
- Withdraw consent at any time, where we rely on consent; and
- Complain to a supervisory authority – the data protection authority where you live or work, or where you believe an infringement took place. In the UK, that’s the Information Commissioner’s Office (ICO); in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC).
To exercise these rights, email privacy@[[your-domain.com]]. We may need to verify your identity first. We’ll respond within one month, which we may extend by up to two more months for complex requests; if we do, we’ll tell you why. We’d appreciate the chance to address your concerns before you contact a supervisory authority.
Children’s privacy
Runzemi is a service for software developers and businesses. You must be at least 18 to use it (see our Terms of Service). We don’t knowingly collect personal information from anyone under 18. If you believe someone under 18 has given us personal information, contact privacy@[[your-domain.com]] and we’ll delete it.
Changes to this policy
We may update this policy as Runzemi changes or as the law requires. We’ll post the new version on this page and update the “Last updated” date above. If we make material changes, we’ll tell you at least 30 days before they take effect, by email or with a notice in the dashboard. Changes required by law or needed to address a security issue may take effect sooner. This version is effective as of .
Contact
Write to us with any questions, requests or complaints about this policy or how we handle personal information.
Company
[[Company legal name, Inc.]][[Street address, City, State ZIP, United States]]
- Privacy requests
- privacy@[[your-domain.com]]
- Support
- support@[[your-domain.com]]
- Security issues
- security@[[your-domain.com]]